CVE-2013-3532 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 5.4% (pctl 92)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the theme parameter.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 5.4% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2013-05-10 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| webdorado | spider video player |
| wordpress | wordpress |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | WordPress Plugin Spider Video Player - 'theme' SQL Injection | 2013-04-11 |
References
- http://osvdb.org/92264
- http://packetstormsecurity.com/files/121250/WordPress-Spider-Video-Player-2.1-SQL-Injection.html
- http://packetstormsecurity.com/files/128851/WordPress-HTML5-Flash-Player-SQL-Injection.html
- http://www.securityfocus.com/bid/59021
- http://www.securityfocus.com/bid/70763
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83374
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98332
- http://osvdb.org/92264
- http://packetstormsecurity.com/files/121250/WordPress-Spider-Video-Player-2.1-SQL-Injection.html
- http://packetstormsecurity.com/files/128851/WordPress-HTML5-Flash-Player-SQL-Injection.html
- http://www.securityfocus.com/bid/59021
- http://www.securityfocus.com/bid/70763
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83374
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98332
→ the Explorer · watch your stack · NVD